Listen to the article
North Korea-linked hackers carried out 99 state-sponsored cyberattacks in the first half of 2026, with an increasing focus on cryptocurrency, AI, and geopolitical targets, marking a significant escalation in its cyber warfare strategy.
North Korea-linked hackers carried out 99 state-sponsored cyberattacks in the first half of 2026, making it the most active state-backed threat actor in the period, according to a new threat intelligence report cited by the Korea Times and produced by South Korean cybersecurity firm S2W. South Korea was the most frequently targeted country, with 19 incidents, while the United States was the second most targeted with eight. The report said combined operations attributed to North Korea, China and Russia reached 158 incidents between January and June, up from 147 in the previous six months.
The findings point to a widening and more industrialised campaign, with North Korea’s activity rising 13.8% compared with the second half of last year. According to S2W, Pyongyang-linked groups have continued to focus on cryptocurrency, IT and software development targets, using fake recruitment efforts, repository infiltration, generative AI and deepfakes to secure access. Separate reporting from South Korean cybersecurity firm AhnLab has also tracked spear-phishing campaigns using malicious LNK and CHM files to deploy backdoors and infostealers.
North Korea’s cyber operations have increasingly become part of a broader economic strategy. CrowdStrike has said one prominent North Korean group, Famous Chollima, accounted for almost half of state-sponsored attacks on US technology companies, using bogus IT job applications, AI-generated identities and forged documents to win remote roles. Reporting from other outlets has likewise described North Korean hackers targeting crypto developers with fabricated corporate profiles and using AI to refine malware, while blockchain security firm Blockaid estimated that North Korea-linked actors stole about $609 million in the first half of 2026, more than half of all verified crypto losses worldwide.
Russia and China also remained active, though with different patterns. S2W said Russian-linked attacks increased 30% to 26 incidents, with Ukraine still the main target, but with additional strikes against Poland and Romania and a growing mix of espionage and disruptive operations. Chinese-linked activity fell 17.5% to 33 incidents, but continued to emphasise long-term espionage against telecommunications networks, alongside expansion into south-east Asia and the Middle East.
Across all three states, the report identified 15 exploited vulnerabilities in 19 incidents during the period, with phishing, public server exploitation and abuse of proxy or cloud services emerging as common techniques. S2W warned that software supply-chain infiltration, persistent access to telecommunications networks and destructive activity tied to geopolitical conflicts are likely to remain central themes in the second half of the year. It also flagged Iran-linked groups as a growing risk to South Korean manufacturing, aviation and energy firms through Middle East-based supply-chain attacks.
Source Reference Map
Inspired by headline at: [1]
Sources by paragraph:
Source: Fuse Wire Services


